1. Scope
This Privacy Policy applies to Alabaster CRM, our related websites, and the support services we provide. An organization that creates an Alabaster tenant controls the customer and contact information placed in that tenant. Alabaster Store LLC processes that information to provide the service and acts on the organization's instructions, except where we use information for our own security, billing, legal, and service-improvement purposes.
In privacy-law terms, the customer organization generally acts as the controller or business for CRM records in its tenant, and Alabaster generally acts as its processor or service provider. Alabaster is the controller for account administration, billing, security, and direct support information that we determine how to use.
2. Information we collect
- Account information, such as names, business contact details, login identifiers, roles, and organization membership.
- CRM information submitted by customers, including contacts, companies, opportunities, appointments, tasks, forms, notes, and custom fields.
- Communications and social information, including messages, message metadata, comments, leads, connected Page or professional Instagram account identifiers, and content a user chooses to publish.
- Integration information, including authorization grants, access tokens, account identifiers, configuration, and synchronization status for connected providers.
- Billing and transaction records. Payment card details may be handled directly by a payment processor rather than stored by Alabaster.
- Technical and usage information, including device and browser information, IP address, authentication events, audit records, error logs, and feature activity.
- Support communications and any information supplied while requesting assistance.
3. How we use information
- Provide, secure, maintain, and troubleshoot Alabaster CRM.
- Authenticate users, enforce permissions, and keep tenant information separated.
- Send and receive communications or publish content when an authorized user requests it.
- Process subscriptions, provide support, and communicate service or security notices.
- Detect fraud, abuse, unauthorized access, and violations of our Terms.
- Comply with law and protect the rights, safety, and integrity of customers, users, Alabaster, and others.
4. Meta and other connected services
When an authorized tenant user connects Facebook, Messenger, Instagram, WhatsApp, Google, or another provider, Alabaster receives only the information and permissions approved during that provider's authorization flow. We use connected-service information to perform requested CRM functions, such as receiving messages, responding to conversations, importing leads, or publishing scheduled content. A tenant administrator can disconnect an integration, and users may also remove Alabaster from the connected provider's settings.
Meta Platform Data may include Page and professional-account identifiers, profile information made available by the approved permission, messages and message metadata, comments, lead information, media or post information, and content an authorized user asks Alabaster to publish. We use that data only to provide the connected feature, maintain security and reliability, comply with law, and support the customer. We do not use Meta Platform Data to build advertising profiles, and we do not sell it.
Removing Alabaster CRM from a provider stops new access after revocation is processed. Disconnecting does not by itself erase data already copied into a customer's tenant; that information can be deleted through the tenant or by following our Data Deletion Instructions.
5. How we share information
We may share information only as needed with:
- The organization that owns the tenant and its authorized users.
- Service providers that support hosting, databases, email, messaging, payments, monitoring, customer support, and security.
- Connected providers when a user directs Alabaster to send, synchronize, or publish information.
- Authorities or other parties when required by law or necessary to prevent harm, fraud, or abuse.
- A successor in a merger, acquisition, financing, reorganization, or sale of business assets, subject to appropriate safeguards.
We do not sell personal information for money or share it for cross-context behavioral advertising.
6. Retention and deletion
We retain information while an account is active and as reasonably necessary to provide the service, resolve disputes, enforce agreements, maintain security records, and satisfy legal obligations. Tenant administrators control much of the information stored in their tenant. Instructions for requesting deletion are available on our Data Deletion page.
Connected-account credentials are retained only while needed to operate an authorized integration and are disabled or removed when the integration is disconnected, expires, or is revoked. After a verified deletion request, eligible information is deleted or anonymized from active systems within 30 days. Limited security, billing, legal, or dispute records may be retained when required or reasonably necessary, and residual encrypted backup copies expire through normal backup-retention cycles.
7. Cookies and similar technologies
We use cookies and similar storage that are necessary to keep users signed in, protect accounts, remember essential settings, and operate the service. We may also measure service reliability and feature usage. We do not use connected social-account data for third-party advertising cookies.
8. Security and international processing
We use administrative, technical, and organizational measures intended to protect information, including access controls, tenant-scoped authorization, encrypted network connections, monitoring, and restricted handling of integration credentials. No method of storage or transmission is completely secure. Information may be processed in the United States and other locations where our service providers operate, subject to applicable safeguards.
9. Your choices and rights
Depending on location and applicable law, individuals may have rights to request access, correction, deletion, portability, restriction, or objection. If an organization entered your information into Alabaster CRM, please contact that organization first because it controls the tenant record. You may also contact us at contact@alabasterautomation.com. We may verify identity and authority before fulfilling a request.
We will not discriminate against a person for exercising an applicable privacy right. An authorized agent may submit a request where permitted by law, but we may require proof of authorization and identity before acting.
10. Children
Alabaster CRM is a business service and is not directed to children under 13. We do not knowingly collect personal information directly from children under 13.
11. Changes and contact
We may update this policy as the service or legal requirements change. We will update the effective date and provide additional notice when appropriate. Questions may be sent to contact@alabasterautomation.com. Business-verification contact information is provided directly to applicable platform and regulatory authorities when required.